CVE-2004-0580

Linksys BEFSR11 BEFSR41 BEFSR81 BEFSRU31 - Information Disclosure via DHCP BOOTP Reply Buffer

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-0580. PoCs published by Jon Hart.

AI-analyzed exploit summary This exploit targets a DHCP server vulnerability in Linksys devices, allowing memory disclosure and potential DoS by sending malformed BOOTP packets. It uses libnet and libpcap to craft and capture packets, revealing sensitive information like admin credentials.

Description

DHCP on Linksys BEFSR11, BEFSR41, BEFSR81, and BEFSRU31 Cable/DSL Routers, firmware version 1.45.7, does not properly clear previously used buffer contents in a BOOTP reply packet, which allows remote attackers to obtain sensitive information.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jon Hart · cremotehardware
https://www.exploit-db.com/exploits/24115

This exploit targets a DHCP server vulnerability in Linksys devices, allowing memory disclosure and potential DoS by sending malformed BOOTP packets. It uses libnet and libpcap to craft and capture packets, revealing sensitive information like admin credentials.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Linksys DHCP server (multiple models including BEFSR41, BEFW11S4, etc.)
No auth needed
Prerequisites: Network access to the vulnerable Linksys device · libnet and libpcap libraries
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16142
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11606
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/6325
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/alerts/2004/May/1010288.html
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108662876129301&w=2
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10329

Scores

EPSS 0.0799
EPSS Percentile 94.0%

Details

Status published
Products (50)
linksys/befcmu10
linksys/befn2ps4
linksys/befn2ps4 1.42.7
linksys/befsr11 1.40.2
linksys/befsr11 1.41
linksys/befsr11 1.42.3
linksys/befsr11 1.42.7
linksys/befsr11 1.43
linksys/befsr11 1.43.3
linksys/befsr11 1.44
... and 40 more
Published Aug 06, 2004
Tracked Since Feb 18, 2026